Latest CVE Feed
-
10.0
HIGHCVE-2004-0433
Multiple buffer overflows in the Real-Time Streaming Protocol (RTSP) client for (1) MPlayer before 1.0pre4 and (2) xine lib (xine-lib) before 1-rc4, when playing Real RTSP (realrtsp) streams, allow remote attackers to cause a denial of service (crash) and... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0505
The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0514
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0425
Heap-based buffer overflow in SiteMinder Affiliate Agent 4.x allows remote attackers to execute arbitrary code via a large SMPROFILE cookie.... Read more
Affected Products : sideminder_affiliate_agent- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0766
NGSEC StackDefender 2.0 allows attackers to cause a denial of service (system crash) via an invalid address for the BaseAddress parameter to the hooks for the (1) ZwAllocateVirtualMemory or (2) ZwProtectVirtualMemory functions.... Read more
Affected Products : stackdefender- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0490
cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which all... Read more
Affected Products : cpanel- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2004-0759
Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an <input type="file"> tag.... Read more
Affected Products : mozilla- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0432
ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass intended access restrictions.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0764
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0513
Unspecified vulnerability in Mac OS X before 10.3.4 has unknown impact and attack vectors related to "logging when tracing system calls."... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0412
Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0761
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0233
Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0520
Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0231
Multiple vulnerabilities in Midnight Commander (mc) before 4.6.0, with unknown impact, related to "Insecure temporary file and directory creations."... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0501
Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, wh... Read more
Affected Products : outlook- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0419
XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0421
The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0476
Buffer overflow in 3Com OfficeConnect Remote 812 ADSL Router 1.1.9.4 allows remote attackers to cause a denial of service (reboot or packet loss) via a long string containing Telnet escape characters to the Telnet port.... Read more
Affected Products : 3cp4144- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0504
Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.... Read more
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025